Welcome to CapitalQ's PCI page that will assist you
with the process of becoming PCI DSS Compliant.
Before You Get StartedRegardless of how you process your credit cards you must insure that your receipts are compliant and that you are storing card data securely. Do not store paper receipts for more than 24 months. Never store paper receipts that have not been truncated to FACTA, state or card association guidelines, especially manual imprinter receipts, without insuring that they are stored in a lock box or safe that cannot be removed from the premises. If you have any question regarding how you store cardholder data, or concerns about your compliance, we strongly recommend that you contact TrustWave to assess your needs. You must determine if you are an IP or Non-IP merchant. If your processing solution connects to the Internet then you are an IP merchant. Below you will see a brief description on each. You can then choose to go straight to TrustKeeper website or go to a CapitalQ page that provides step by step instructions for registering and starting the process. This video from the PCI Security Council explains the 12 requirements. Kind of hokey but it gets the point across. PCI Data Security Rock |
Go Back to |
IP Solutions
If you offer online payment options to your customers, then you utilize an Internet gateway or online shopping cart to process credit and debit card transactions. Alternately, if you process credit or debit cards via an internet connection or a cash register system that utilizes third-party software, then you also use an IP Solution.
Avoid Common Mistakes for Storing Cardholder Data
- Cardholder information should never be stored on any employee workstation. If it is, this data needs to be properly secured and must adhere to PCI standards for encryption software that protects sensitive data.
NON-IP Solutions
You use a non-IP payment acceptance method if you process payments via a dial-up terminal, an ARU (Touchtone) or paper method. Most standard dial-up point-of-sale terminals are certified as PCI compliant and do not store card data if used, maintained, and programmed properly. If you use an ARU or paper method, or to confirm that your procedures for handling cardholder data meet current PCI-DSS regulations, click on the Receipt Truncation and Secured Card Holder Data tabs.
Merchant Accounts | Credit Card Processing | Internet Credit Card Processing | Merchant Account | Accept Debit Cards
Accept Credit Cards | Credit Card Equipment | Credit Card Terminals| Credit Card Processing Rates | Contact CapitalQ





Comment